summary refs log tree commit diff
path: root/nixos/modules/security/wrappers
diff options
context:
space:
mode:
authorParnell Springmeyer <parnell@digitalmentat.com>2017-01-29 16:47:14 -0600
committerParnell Springmeyer <parnell@digitalmentat.com>2017-01-29 16:47:14 -0600
commit4856b42ab69beb882414664551f1ca879d379936 (patch)
tree0b43b76ee3c5bc719c388c76cf5ac66d1e5e12d0 /nixos/modules/security/wrappers
parent9abe7528e4c495c868fa518af50c3cdfd1e755ed (diff)
downloadnixlib-4856b42ab69beb882414664551f1ca879d379936.tar
nixlib-4856b42ab69beb882414664551f1ca879d379936.tar.gz
nixlib-4856b42ab69beb882414664551f1ca879d379936.tar.bz2
nixlib-4856b42ab69beb882414664551f1ca879d379936.tar.lz
nixlib-4856b42ab69beb882414664551f1ca879d379936.tar.xz
nixlib-4856b42ab69beb882414664551f1ca879d379936.tar.zst
nixlib-4856b42ab69beb882414664551f1ca879d379936.zip
Gotta provide sane defaults! This is what I get for 5AM coding
Diffstat (limited to 'nixos/modules/security/wrappers')
-rw-r--r--nixos/modules/security/wrappers/default.nix8
1 files changed, 7 insertions, 1 deletions
diff --git a/nixos/modules/security/wrappers/default.nix b/nixos/modules/security/wrappers/default.nix
index 9909c6406471..cb288fc08809 100644
--- a/nixos/modules/security/wrappers/default.nix
+++ b/nixos/modules/security/wrappers/default.nix
@@ -79,7 +79,13 @@ let
              (s ? "setguid" && s.setguid == true) ||
              (s ? "permissions")
           then mkSetuidProgram s
-          else ""
+          else mkSetuidProgram
+                 ({ owner  = "root";
+                    group  = "root";
+                    setuid = true;
+                    setgid = false;
+                    permissions = "u+rx,g+x,o+x";
+                  } // s)
       ) programs;
 in
 {